LIVE · cybersecurity feed
Live wire
roundcubehigh

Suspected Chinese Threat Group Targets Universities via Vulnerable Roundcube Servers

A sophisticated threat group, believed to be operating from China, is actively exploiting security weaknesses in Roundcube webmail servers. Their objective is to gain unauthorized access to university networks across the United States and Canada, with the ultimate goal of stealing user login information.

zeroday.news · 25d ago

A suspected China-aligned threat group, tracked by researchers as UNK_MassTraction, has been actively exploiting vulnerabilities in Roundcube webmail servers to gain access to academic institutions in the United States and Canada. The primary targets appear to be physics and engineering departments, with potential connections to national security interests.

The attackers leveraged multiple known vulnerabilities in Roundcube to compromise these mail servers. Proofpoint, a cybersecurity firm that published research on the activity on June 7, observed that the threat group used these compromised servers not just for email data theft, but as an entry point into victim networks. This aligns with a broader trend of China-aligned operators exploiting internet-facing infrastructure, including edge devices and public applications, to achieve initial network access.

One key method employed by UNK_MassTraction involved phishing emails containing malicious content designed to exploit CVE-2024-42009, a cross-site scripting (XSS) vulnerability within Roundcube. When a user interacted with a vulnerable webmail client, this exploit allowed malicious JavaScript to execute within their browser. This JavaScript payload, identified by Proofpoint as IceCube, was designed to steal sensitive information such as usernames, passwords, cookies, and authentication data. The malware also collected environmental information from the victim's system, and the stolen session data was then used to facilitate further compromise.

Following the initial compromise of the Roundcube server, the threat actors exploited another vulnerability, CVE-2025-49113, which is described as a deserialization vulnerability. This allowed them to deploy a webshell for remote access or install the VShell backdoor directly into the server's memory. VShell is a publicly available remote access tool written in Go, and Proofpoint noted its previous use by China-aligned threat actors across Windows, Linux, and macOS environments.

The VShell backdoor provides attackers with interactive shell access and port-forwarding capabilities, enabling them to move laterally and deepen their presence within the compromised networks. Researchers assessed that the targeting strategy, infrastructure connections, and the presence of Chinese language artifacts in some phishing emails strongly suggest that UNK_MassTraction's operations are focused on espionage.

Proofpoint's analysis indicates that the attackers employed a range of techniques throughout the infection chain. These included credential theft via malicious JavaScript, server-side exploitation of vulnerable Roundcube components, deployment of webshells for persistent access, and memory-based execution of the VShell backdoor to evade detection.

The campaign serves as a reminder that email servers, like other internet-facing devices, remain attractive targets for threat actors. China-aligned operators, in particular, continue to treat these systems as critical entry points for network compromise.

Defenders are advised to prioritize the security of their mail servers with the same rigor applied to other remote access nodes, such as VPN concentrators. This includes ensuring that all software, including webmail applications like Roundcube, is kept up-to-date with the latest security patches to mitigate known vulnerabilities.

roundcubevulnerabilityespionageeducationchina
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time. Galaxy Research mapped the sweep and tied it to a firmware flaw in Coldcard, the Bitcoin-only hardware wallet made by Canadian firm Coinkite. A March 2021 firmware integration error routed seed generation to a deterministic software pseudorandom number generator (PRNG

vulnerabilitycritical

Rails patches critical Active Storage flaw with RCE potential

A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE). [...]

malware

Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens

Microsoft says Russian hackers hijacked hotel Wi-Fi portals to spread malware and steal Microsoft 365 tokens from travelers. Microsoft Threat Intelligence disclosed CaptiveCrunch, a campaign it attributes to Storm-2945, an operational sub-cluster of Midnight Blizzard, the Russian SVR-linked group also known as APT29 and Cozy Bear. Since early May 2026, Storm-2945 has been manipulating DNS […]

CVE-2026-48449critical

Adobe fixed a maximum-severity vulnerability flaw in Campaign Classic

Adobe fixed a maximum severity vulnerability in Campaign Classic that could let attackers run code remotely without user interaction. Adobe has addressed a critical vulnerability, tracked as CVE-2026-48449 (CVSS score of 10.0), in Adobe Campaign Classic, the company’s enterprise marketing automation platform. The flaw is caused by incorrect authorization and could allow attackers to execute […]

security

Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments

The funding round was led by SYN Ventures, with participation from existing investors DataTribe and TEDCO. The post Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments appeared first on SecurityWeek.

vulnerabilitycritical

Ruby on Rails Patches Critical Vulnerability

The flaw can be exploited by unauthenticated attackers to read arbitrary files and potentially achieve remote code execution (RCE). The post Ruby on Rails Patches Critical Vulnerability appeared first on SecurityWeek.